DATA PROTECTION POLICY
Purpose:
This policy provides guidance on how NAIVAS will handle the data it collects.
It ensures compliance with data protection laws, safeguards the rights of data subjects, and mitigates risks associated with data breaches.
Policy Statement:
NAIVAS is committed to adhering to all relevant Kenyan legislation and applicable global data protection regulations.
The company acknowledges that lawful, legitimate, and responsible processing and use of personal data is a fundamental human right.
NAIVAS will ensure that the rights of data subjects are protected and that any data collected or processed aligns with legal requirements.
All NAIVAS employees must comply with this policy. Any breach may result in disciplinary action.
The Board is responsible for ensuring that adequate and effective systems and processes are in place to safeguard data.
Implementation & Compliance:
NAIVAS will implement measures to securely collect, store, and process personal data.
Employees will receive training to ensure awareness and compliance with data protection laws.
Any suspected data breaches must be reported immediately to the relevant authorities within NAIVAS.
Regular audits will be conducted to assess adherence to this policy and identify areas for improvement.
Review & Amendments:
This policy will be reviewed periodically to reflect changes in legislation and best practices in data protection.
